Back Defendwork Apple zero-day, Microsoft mega-patch (974 CVEs), ShinyHunters Oracle escalation
Apple patched a CoreGraphics zero-day possibly exploited in targeted attacks; Microsoft issued its largest patch batch ever (974 vulnerabilities); ShinyHunters escalated attacks after a member's arrest in the Netherlands, now exploiting Oracle PeopleSoft workarounds.
Apple released security updates for CVE-2026-86950, a CoreGraphics out-of-bounds write in iOS, iPadOS, and macOS that may have been exploited in targeted attacks.
Microsoft published its largest security update ever, addressing at least 974 vulnerabilities across Windows and other products, with AI cited as a discovery accelerant.
ShinyHunters hacking group escalated attacks after a 23–24 year old member's arrest in Amsterdam, now using modified exploits against Oracle PeopleSoft vulnerability CVE-2026-35273 .
Cryptocurrency exchange Bitget confirmed a $388 million theft exploited a third-party security product vulnerability, not an exchange platform flaw.
Misconfigured Supabase databases exposed over 16,000 instances containing PII, passwords, and authentication tokens.
1. Apple CoreGraphics Zero-Day Possibly Exploited
Severity: HIGH Affected: Technology
Apple has released security updates to address CVE-2026-86950, an out-of-bounds write vulnerability in the CoreGraphics component affecting older versions of iOS, iPadOS, and macOS [1] . The company stated the flaw may have been exploited in targeted attacks [1] . Specific version numbers and patch details were not disclosed in available reports. Sources: [1] The Hacker News
Prioritize updates to iOS, iPadOS, and macOS devices, particularly in organizations managing high-value targets
Monitor endpoints for suspicious CoreGraphics-related process behavior or memory corruption crashes
Review logs for any indicators of targeted attack activity on Apple platforms
2. Microsoft Patches Record 974 Vulnerabilities
Severity: HIGH Affected: Technology
Microsoft Corp. issued updates to plug at least 974 security holes in Windows operating systems and other software, representing its largest single patch batch ever [1] . The company cited artificial intelligence as a tool helping to speed vulnerability discovery, though security experts warn many of the newly patched flaws may have been unknown to defenders until now [1] . Sources: [1] Krebs on Security
Establish an expedited testing and deployment schedule for the Microsoft patch batch
Prioritize Windows systems and commonly-targeted Microsoft products (Office, Exchange, Edge)
Verify patch applicability to your environment and test in isolated infrastructure before broad deployment
3. ShinyHunters Escalate Attacks on Oracle PeopleSoft After Member Arrest
Severity: HIGH Affected: Technology
Dutch police arrested a 23–24 year old convicted cybercriminal in connection with the prolific ShinyHunters hacking group; in the days following the arrest, remaining ⚠ ShinyHunters members dramatically escalated their attack activity [1] . The group is now exploiting CVE-2026-35273, a vulnerability in Oracle PeopleSoft, using modified exploits in targeted campaigns [2] [3] . Mandiant researchers and Google have both warned of this escalating activity [2] [3] . Sources: [1] Krebs on Security [2] The Record [3] SecurityWeek
Audit Oracle PeopleSoft instances for unauthorized access and patch CVE-2026-35273 immediately
Review authentication logs for brute-force attempts or unusual credential usage against PeopleSoft systems
Monitor for data exfiltration from HR, payroll, and financial modules targeted by ShinyHunters in prior campaigns
4. Bitget Cryptocurrency Exchange Loses $388M via Third-Party Security Product Flaw
Severity: HIGH Affected: Finance
Bitget cryptocurrency exchange disclosed a theft of approximately $388 million; the attacker exploited a vulnerability in a third-party security product used by the exchange to obtain high-level internal credentials [1] . On September 24, the attacker used those credentials to access and drain cryptocurrency holdings ⚠ [1] . This incident highlights supply-chain risks in security tooling itself. Sources: [1] The Hacker News
Audit all third-party security products and admin tools for known vulnerabilities and credential exposure
Implement privileged access management (PAM) to limit exposure of high-level internal credentials
Review transaction logs and withdrawal activity for anomalies in the 30 days prior to and following September 24, 2026
5. Over 16,000 Supabase Databases Misconfigured, Exposing Credentials and PII
Severity: HIGH Affected: Technology
Researchers discovered more than 16,000 misconfigured Supabase databases exposing readable tables containing personally identifiable information, passwords, and authentication tokens [1] . Supabase is a widely-used backend-as-a-service platform; the scale of exposure indicates systematic configuration errors across a large developer base. Sources: [1] BleepingComputer
If you operate Supabase instances, immediately verify row-level security (RLS) policies are enabled and correctly configured
Rotate any credentials or API keys that may have been exposed through misconfigured databases
Audit recent access logs for unauthorized data access attempts
Citrix NetScaler CVEs: Earlier coverage of CVE-2026-88771 and CVE-2026-88772 remains current; both are now in CISA's Known Exploited Vulnerabilities catalog with federal remediation deadline 2026-09-30 [31, 32].
NeedyMantis Malware: Microsoft reports the NeedyMantis malware family is being used to maintain long-term access in targeted intrusions at telecommunications, university, and medical nonprofit organizations [2].
RatHat Android Banking Trojan: Cleafy reports the RatHat Android banking trojan malware-as-a-service model, with nearly 100 deployed command consoles traced since April 2026 and operators using AI (Gemini) to identify higher-value victims [5].
JadePuffer Agentic Ransomware on Azure: JadePuffer ransomware operators are conducting agent-driven attacks against Azure tenants, performing reconnaissance, stealing credentials, and destroying cloud resources [10].
Arrests & Sentencing: Dutch police confirmed a 24-year-old Amsterdam resident arrested in connection with ShinyHunters [8]. A U.S. Army soldier was sentenced to 70 months in federal prison for hacking AT&T, Verizon, and other telecom companies, stealing call and text metadata for over 100 million AT&T customers [12].
Today’s Action Checklist
☐ URGENT: Deploy Microsoft's 974-vulnerability patch batch to Windows and Microsoft products on an expedited timeline
☐ URGENT: Audit Oracle PeopleSoft systems for CVE-2026-35273 and apply patches; review authentication and data access logs
☐ Update iOS, iPadOS, and macOS to latest versions addressing CVE-2026-86950
☐ If using Supabase, verify row-level security policies are enabled and audit for unauthorized access
☐ Review third-party security tools and admin credentials for exposure; implement privileged access management controls
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
